CVE-2021-46757

HIGH
Published Feb 13, 2024 Modified May 7, 2025 CWE-119

Description

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.

Is your site exposed to CVE-2021-46757?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-119 Buffer Overflow

Affected Products

Vendor Product
amd ryzen_embedded_5950e_firmware
amd ryzen_embedded_5950e
amd ryzen_embedded_5900e_firmware
amd ryzen_embedded_5900e
amd ryzen_embedded_5800e_firmware
amd ryzen_embedded_5800e
amd ryzen_embedded_5600e_firmware
amd ryzen_embedded_5600e
amd ryzen_embedded_v2516_firmware
amd ryzen_embedded_v2516
amd ryzen_embedded_v2546_firmware
amd ryzen_embedded_v2546
amd ryzen_embedded_v2718_firmware
amd ryzen_embedded_v2718
amd ryzen_embedded_v2748_firmware
amd ryzen_embedded_v2748
amd ryzen_embedded_r2312_firmware
amd ryzen_embedded_r2312
amd ryzen_embedded_r2314_firmware
amd ryzen_embedded_r2314

References

Frequently Asked Questions

What is CVE-2021-46757? +
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation. It has a CVSS v3.1 base score of 7.8 (HIGH).
How severe is CVE-2021-46757? +
CVE-2021-46757 has a CVSS v3.1 score of 7.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2021-46757? +
CVE-2021-46757 affects products from amd, specifically: ryzen_embedded_5600e, ryzen_embedded_5600e_firmware, ryzen_embedded_5800e, ryzen_embedded_5800e_firmware, ryzen_embedded_5900e, ryzen_embedded_5900e_firmware, ryzen_embedded_5950e, ryzen_embedded_5950e_firmware, ryzen_embedded_r2312, ryzen_embedded_r2312_firmware, ryzen_embedded_r2314, ryzen_embedded_r2314_firmware, ryzen_embedded_v2516, ryzen_embedded_v2516_firmware, ryzen_embedded_v2546, ryzen_embedded_v2546_firmware, ryzen_embedded_v2718, ryzen_embedded_v2718_firmware, ryzen_embedded_v2748, ryzen_embedded_v2748_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2021-46757? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2021-46757 — free, no signup required.